azure-app-onboard
microsoft/azure-skills
Execute validated Infrastructure-as-Code against Azure with health verification and deployment tracking.
What is azure-app-onboard?
This skill executes Infrastructure-as-Code (IaC) templates against Azure after validation, performs health checks on deployed resources, and tracks deployment status. Use it as part of the azure-app-onboard orchestrator workflow (Phase 4) when you have a validated scaffold manifest ready for deployment.
- Executes ARM/Bicep templates against Azure subscriptions with mandatory what-if preview
- Performs health checks on deployed resources via HTTP endpoints and response validation
- Automatically generates and manages secure parameters (passwords, keys) without user input
- Deploys application code to all services defined in the deployment plan
- Re-disables SCM (Source Control Management) credentials on App Services after deployment
- Tracks deployment status, errors, and healing attempts in structured artifacts
How to install azure-app-onboard
npx skills add https://github.com/microsoft/azure-skills --skill azure-app-onboard- Azure CLI (az) installed and authenticated
- Valid prepare-plan.json and scaffold-manifest.json from prior orchestrator phases
- Appropriate Azure RBAC permissions for deployment and resource group management
- Access to the .copilot-azure/sessions/{id}/ directory for artifact reading/writing
How to use azure-app-onboard
- 1.Ensure prepare-plan.json and scaffold-manifest.json exist in your session directory
- 2.The skill dispatches a preflight sub-agent to generate deploy-checklist.md with validation steps
- 3.Review the deployment cost and resource summary at the approval gate
- 4.Confirm deployment to proceed with IaC execution and code deployment
- 5.Monitor health checks and healing loops; the skill auto-generates deploy-result.json with final status
Use cases
- Deploy a multi-service Azure application (App Service, Functions, databases) from validated IaC
- Verify deployed resources are healthy and responding correctly before handoff
- Execute deployment with automatic cost/resource approval gates and portal link generation
- Recover from transient deployment failures with intelligent healing loops
- Track deployment artifacts and generate summary reports for audit/documentation
- Azure solution architects executing Infrastructure-as-Code workflows
- DevOps engineers automating multi-service application deployments
- Cloud engineers verifying resource health post-deployment
- Teams using the azure-app-onboard orchestrator for end-to-end app deployment
azure-app-onboard FAQ
Automatically by the azure-app-onboard orchestrator at Phase 4 when scaffold-manifest.json exists with validated files and validationResult. It is not directly user-routable.
The skill classifies the error, attempts healing (up to 3 times, then every 5 attempts), and asks for user intervention if unrecoverable. It always writes deploy-result.json with status 'failed' and errorDetails before returning to the orchestrator.
The skill auto-generates all @secure() parameters using cryptographic randomization; it never asks users for passwords. On retry, it reuses secrets from deploy-secrets.env or Key Vault to avoid regeneration.
HTTP GET requests to endpoints, response body inspection for error patterns (MODULE_NOT_FOUND, connection refused, localhost), and verification that SCM credentials are disabled on App Services.
deploy-result.json (deployment status and endpoints), deployment-summary.md (summary report with portal links and cleanup commands), and updates to context.json to mark the deploy phase complete.
Full instructions (SKILL.md)
Source of truth, from microsoft/azure-skills.
Deploy — IaC Execution & Health Verification
Quick Reference
| Property | Value |
|---|---|
| Best for | Executing validated IaC against Azure, health-checking deployed resources |
| Inputs | prepare-plan.json + scaffold-manifest.json from .copilot-azure/sessions/{id}/ |
| Outputs | deploy-result.json written to session directory |
| Parent | azure-app-onboard |
When to Use This Skill
Invoked by the azure-app-onboard orchestrator at Phase 4 when scaffold-manifest.json exists with files[] and validationResult. Not directly user-routable.
Return to orchestrator: When complete, return control to
azure-app-onboardfor handoff (Step 10). Do NOT start new phases.
When NOT to Use
| Scenario | Use Instead |
|---|---|
| Plan architecture, map services, estimate costs | prepare |
| Generate IaC files from a plan | azure-app-onboard Step 7 (scaffold) |
Run azd up or execute existing deployment templates | azure-deploy |
| Debug a running app after deployment | azure-diagnostics |
| Optimize existing Azure spending | cost-optimization from the optional azure-cost plugin |
If cost-optimization is unavailable, explain that it is provided by the
optional azure-cost plugin and direct the user to their client's supported
plugin installation flow; do not imply the handoff completed.
Workflow
⛔ Sub-agent delegation is MANDATORY for Step 0. Read
subagent-preflight.md, then dispatch as ataskwith the COMPLETE and UNMODIFIED template text between<<<TEMPLATE_START>>>/<<<TEMPLATE_END>>>delimiters. Do NOT summarize or rewrite the template — the sub-agent needs every "Read [file]" instruction to produce a correctdeploy-checklist.md. Append session artifact data AFTER the template block. If your next action after reading the template is anything other thantask, you are executing it inline instead of delegating.
⛔ Healing loop: ask user after 3 attempts, then every 5 (counter =
healingAttempts[].length).
⛔ Region lock: Before
az deploymentretry, compare--locationagainstprepare-plan.json.deploymentVariables.location. If changed → re-approval gate required. Update plan after approval.
⛔ After compaction or any
az deployment/az webapp deploy/az acr build/failed health check: re-readdeploy-checklist.md. If missing → fill fromdeploy-checklist-template.md. On significant context loss: also re-read this SKILL.md.
| # | Step | Action | Artifact | Reference |
|---|---|---|---|---|
| 0 | Dispatch preflight sub-agent | ⛔ You MUST dispatch subagent-preflight.md as a task. ⛔ agent_type: "task" — NEVER "general-purpose". Read the template, then your NEXT action MUST be task. If after reading the template your next action is powershell, view, or anything other than task, STOP — you are executing inline instead of delegating. Writes deploy-checklist.md. view it immediately after return. | deploy-checklist.md | ⛔ You MUST read subagent-preflight.md |
| 1 | Read upstream artifacts | Load prepare-plan.json + scaffold-manifest.json. Check validationResult. Resolve subscription + deployment variables. | — | — |
| 3 | Preflight checks | Auth, mandatory what-if preview, RBAC, RG per deploy-checklist.md § Preflight. | — | ⛔ You MUST read deploy-checklist.md (re-read if compaction occurred) |
| 4 | Deploy approval gate | Present cost + resource summary per deploy-checklist.md § Deploy approval gate format. | — | — |
| 5b | Write deploy-result.json skeleton | ⛔ Read deploy-schemas.ts, write skeleton (status: "in-progress"). Must exist BEFORE first az command. | deploy-result.json | ⛔ You MUST read deploy-schemas.ts |
| 6 | Execute deployment | ⛔ BEFORE az deployment sub create: Generate portal link — $dn="{deploymentName}"; $r="/subscriptions/{subId}/providers/Microsoft.Resources/deployments/$dn"; $l="https://portal.azure.com/#view/Microsoft_Azure_Resources/DeploymentDetails.MenuView/~/overview/id/$($r.Replace('/','%2F'))"; Write-Output "LINK=$l". ⛔ Auto-open link in browser: Start-Process $l 2>$null. Print bare URL in chat (ctrl-clickable).<br>Auto-generate ALL @secure() params (openssl rand -base64 32 | tr -d '/+='), NEVER ask_user for passwords; on retry reuse from deploy-secrets.env or Key Vault — NEVER regenerate (see deploy-safety.md § Deploy Checklist). THEN deploy IaC. | — | ⛔ You MUST read deploy-checklist.md § Execute deployment |
| 6b | Deploy application code | ⛔ Deploy code for EVERY service in prepare-plan.json.services[]. Follow deploy-checklist.md § Code deploy. | — | ⛔ You MUST read deploy-checklist.md § Code deploy |
| 7 | Health-check + SCM re-disable | HTTP GET per endpoint (max 3 iterations). ⛔ Multi-service apps: Also inspect the response body for error patterns (connection refused, MODULE_NOT_FOUND, localhost, SET-IN-DEPLOY-PHASE) — HTTP 200 alone does not mean functional when the app depends on another service or KV secrets. Then ⛔ for EVERY App Service/Functions app run BOTH commands — no exceptions: az rest --method put --url "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app}/basicPublishingCredentialsPolicies/scm?api-version=2023-12-01" --headers "Content-Type=application/json" --body '{"properties":{"allow":false}}' then verify: az rest --method get --url "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app}/basicPublishingCredentialsPolicies/scm?api-version=2023-12-01" --query properties.allow -o tsv (must return false). | deploy-result.json full | ⛔ You MUST read deploy-checklist.md § Health check |
| 8 | Finalize artifacts | ⛔ Read deploy-schemas.ts. ⛔ Re-read deploy-checklist.md § Artifact verification — follow ALL 5 checks. ⛔ No "live"/handoff message until you overwrite the skeleton deploy-result.json — flip status off "in-progress" (→ succeeded/failed) and fill healthStatus, endpoints, completedUtc, deploymentNames, healingAttempts. Write deployment-summary.md (status table + health + portal link(s) + cleanup commands — same content as your handoff message). Update context.json — add "deploy" to completedPhases, currentPhase: null, lastModifiedUtc. Read back to confirm status != "in-progress" and "deploy" ∈ completedPhases. ⛔ Then STOP — return to orchestrator. No further CLI commands. | deploy-result.json final + deployment-summary.md + context.json update | ⛔ You MUST read deploy-schemas.ts + ⛔ Re-read deploy-checklist.md § Artifact verification |
| 9 | Error handling + healing | ⛔ Only if Steps 6/6b/7 returned nonzero exit code or health check failed. Skip entirely on clean deploys. Classify errors, healing loop, PLAN_LEVEL_CHANGE re-approval per deploy-checklist.md § During healing. ⛔ Even on unrecoverable failure: write deploy-result.json with status: "failed" and errorDetails before returning to orchestrator — the artifact must always exist. | — | ⛔ You MUST read error-classification.md |
Related skills
More from microsoft/azure-skills and the wider catalog.

azure-app-onboard-prereq
Assess whether your source code is ready to deploy to Azure before infrastructure work.

azure-cloud-migrate
Assess and migrate cross-cloud workloads to Azure with automated code conversion and reports.

azure-compliance
Run Azure compliance and security audits with azqr and Key Vault expiration checks.

azure-compute
Route Azure VM and VMSS provisioning, sizing, pricing, and capacity reservation requests to the right workflow.

azure-cost
Query Azure costs, forecast spending, and optimize resource usage to reduce waste.

azure-cost-optimization
Identify Azure cost savings from usage data and orphaned resources.